The vendor explicitly identifies these products as affected by this CVE.
- workload-availability/node-remediation-console-rhel8 as a component of Node HealthCheck Operator
- container-native-virtualization/kubevirt-console-plugin as a component of Red Hat OpenShift Virtualization 4
- container-native-virtualization/kubevirt-console-plugin-rhel9 as a component of Red Hat OpenShift Virtualization 4
- Summary
- A prototype pollution vulnerability was found in DOMPurify. This flaw allows a remote attacker to add or modify attributes of an object prototype. This issue can lead to the injection of malicious attributes used in other components or cause a crash by overriding existing attributes with ones of incompatible type.
- Remediation
- If you are using an earlier version of RHACS 4.4, you are advised to upgrade to this patch release 4.4.6.
